All CVEs — page 3 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The vulnerability in Moore Threads MTT S80 Driver Package 340.150 allows local attackers to exploit improper privilege management, leading to potential high impact on system integrity and availability.
The flaw allows attackers to trigger GPU memory exhaustion by submitting multiple completion requests, leading to orphaned KV cache blocks and preventing legitimate requests from executing.
The flaw allows attackers to allocate unbounded memory by supplying arbitrary tp_size values, potentially leading to a denial of service via kernel OOM-kill.
The vulnerability allows attackers to send rejected prefill requests that create ownerless transfer placeholders, leading to resource exhaustion and delayed processing of valid requests.
The vulnerability allows attackers to create unreachable peer sessions that exhaust ZeroMQ socket quotas, leading to EngineCore crashes and service disruptions.
The flaw allows attackers to trigger an assertion failure in vLLM's NIXL connector by submitting multi-prompt completion requests, leading to service disruption.
The flaw allows attackers to cause a denial of service by sending requests with incomplete metadata entries, leading to engine termination and failure of routed requests.
DesktopSMS 1.11.0 allows local attackers to transmit and retrieve SMS content without user interaction due to an unauthorized access vulnerability.
The flaw allows authenticated users to read any employee's roles and permissions by exploiting the unvalidated employeeId parameter, posing a security risk.
The vulnerability allows authenticated users to delete other users' notifications without proper validation, enabling unauthorized data modification.
The flaw allows authenticated attackers to modify any user's profile fields, including nicknames and avatars, by exploiting PUT requests to specific endpoints.
This vulnerability allows authenticated users to download any file stored by other users due to a lack of proper file ownership validation, enabling unauthorized access to sensitive information.
The flaw allows authenticated users to read other users' full profiles, including sensitive information like mobile numbers and national identity card numbers.
The flaw allows unauthenticated attackers to exploit a password reset link poisoning vulnerability by manipulating the client-supplied origin parameter, leading to potential full account takeover.